Page 2 of 3 FirstFirst 123 LastLast
Results 11 to 20 of 28

Thread: Random programs and services trying to gain 'net access.

  1. #11
    voivod Guest

    Default Re: Random programs and services trying to gain 'net access.

    Strange ZA alerts are still happening.
    The email client (Forte' Agent) that I've used for at least 8 years with ZA for the very first time tonight requested to be allowed to run as a server. Listening on 0.0.0.0:61444
    What the heck is going on!


    Edit - Decided to run another virus scan. Went to update AVG in the middle of downloading the update got five or six requests to allow the AVG updater to act as a server. I'm really starting to get freaked out by this!

    Message Edited by Voivod on 04-21-2008 10:17 PM

    Message Edited by Voivod on 04-21-2008 10:17 PM

  2. #12
    Join Date
    Dec 2002
    Location
    Mikado Michigan
    Posts
    2,596

    Default Re: Random programs and services trying to gain 'net access.

    I think I am starting to understand what is going on with your machine. The alerts are slightly misleading. When you get a popup saying that a program is trying to contact the internet, you need to look at the IP address's. There are three subnets that are private. They are for local LAN's and are not routable out over the internet. They are 10.0.0.0 - 10.255.255.255, 172.16.0.0 - 172.31.255.255, 192.168.0.0 - 192.168.255.255 . There are a few other address's that are also reserved. 169.254.0.0 - 169.254.255.255 are reserved for Link-Local connections (don't ask) and they are seen a lot when a NIC cannot get a lease on an IP address. Also there is 0.0.0.0 (Your computer) and 224.0.0.0 - 224.0.0.255 (which is reserved for multicasting).

    ZoneAlarm is going to control ANY TCP/IP traffic, even if it is from your computer to your computer. What you are seeing is this kind of traffic. So there is no reason to panic. What I am wondering is why these things keep asking for permission. The ones that you deny will ask every time they run, if the program is set to ask. Is this what is happening?
    My homes are SpywareHammer.com and DonHoover.net and BleepingComputer.com


    Consumer Security - 2011 & 2012

    Tilting at windmills hurts you more than the windmills.
    -From the Notebooks of Lazarus Long
    Senior of the Howard Families

  3. #13
    voivod Guest

    Default Re: Random programs and services trying to gain 'net access.

    I understand the private netwoking subnets (have held Cisco certs in the past). I'm more interested in and worried about the underlying cause of these alerts. I've had the machine running for months and this just
    recently started. I've run ZA and my email client together for years and until today I'd never seen an alert saying it wanted to act as a server. **bleep** it CAN'T.
    The programs and services don't always try to make connections. It's randomly hit or miss.
    I can't figure out what's triggering it. It'll be running fine for hours and then sudddenly ZA will pop off an alert on something new or I'll check the log and the screen saver's (blocked)
    made several attempts in a row. There's no rhyme or reason to it.

  4. #14
    Join Date
    Dec 2002
    Location
    Mikado Michigan
    Posts
    2,596

    Default Re: Random programs and services trying to gain 'net access.

    Can you post up part of zalog.txt? It's the raw log that is displayed in the logviewer. I need a section that shows these events. If you don't want to post it, you should be able to see my e-mail address in my profile. If you send me the log, add a link to this thread so I know for sure what its about.
    My homes are SpywareHammer.com and DonHoover.net and BleepingComputer.com


    Consumer Security - 2011 & 2012

    Tilting at windmills hurts you more than the windmills.
    -From the Notebooks of Lazarus Long
    Senior of the Howard Families

  5. #15
    voivod Guest

    Default Re: Random programs and services trying to gain 'net access.

    I'll have to turn the logging back on. Will mail it to you when we catch something

  6. #16
    voivod Guest

    Default Re: Random programs and services trying to gain 'net access.

    No email listed in your profile

  7. #17
    voivod Guest

    Default Re: Random programs and services trying to gain 'net access.

    Guess I can't send it....
    Some creative editing done to reduce size...

    ZoneAlarm Logging Client v7.1.248.000
    Windows Vista-6.0.6000--SMP
    type,date,time,source,destination,transport (Security)
    type,date,time,virus name,file name,mode,e-mail id (Anti-Virus)
    type,date,time,source,destination,action,service (IM Security)
    type,date,time,source,destination,program,action (Malicious Code Protection)
    type,date,time,action,product,file,event,subevent, class,data,data,... (OSFirewall)
    type,date,time,name,type,mode (Anti-Spyware)
    FWIN,2008/04/23,01:14:24 -4:00 GMT,221.209.110.12:35933,68.205.1.14:1027,UDP
    FWIN,2008/04/23,01:14:48 -4:00 GMT,221.208.208.90:33581,68.205.1.14:1026,UDP
    ACCESS,2008/04/23,01:14:58 -4:00 GMT,Desktop Window Manager was blocked from connecting to the Internet (239.255.255.250).,N/A,N/A
    ACCESS,2008/04/23,03:39:08 -4:00 GMT,Desktop Window Manager was blocked from connecting to the Internet (239.255.255.250).,N/A,N/A
    ACCESS,2008/04/23,04:17:18 -4:00 GMT,Desktop Window Manager was blocked from connecting to the Internet (239.255.255.250).,N/A,N/A
    ACCESS,2008/04/23,05:13:16 -4:00 GMT,Desktop Window Manager was blocked from connecting to the Internet (224.0.0.252).,N/A,N/A
    PE,2008/04/23,05:49:20 -4:00 GMT,Modem Audio Service,C:\Windows\System32\drivers\XAudio.exe,10. 193.96.1:0,N/A
    ACCESS,2008/04/23,05:50:40 -4:00 GMT,Modem Audio Service was temporarily blocked from connecting to the Internet (10.193.96.1).,N/A,N/A
    ACCESS,2008/04/23,06:15:24 -4:00 GMT,Desktop Window Manager was blocked from connecting to the Internet (239.255.255.250).,N/A,N/A
    ACCESS,2008/04/23,07:12:34 -4:00 GMT,Desktop Window Manager was blocked from connecting to the Internet (239.255.255.250).,N/A,N/A
    ACCESS,2008/04/23,07:32:40 -4:00 GMT,Desktop Window Manager was blocked from connecting to the Internet (224.0.0.252).,N/A,N/A
    FWIN,2008/04/23,07:42:42 -4:00 GMT,213.207.178.1:0,68.205.1.14:0,ICMP (type:8/subtype:0)
    FWIN,2008/04/23,08:22:02 -4:00 GMT,91.171.30.202:2363,68.205.1.14:21286,TCP (flags:S)
    PE,2008/04/23,08:22:40 -4:00 GMT,Adobe Flash Player Helper 9.0
    r115,C:\Windows\System32\Macromed\Flash\FlashUtil9 e.exe,224.0.0.252:0,N/A
    FWIN,2008/04/23,08:23:44 -4:00 GMT,91.171.30.202:2423,68.205.1.14:21286,TCP (flags:S)
    FWIN,2008/04/23,08:53:10 -4:00 GMT,221.208.208.100:49779,68.205.1.14:1026,UDP
    ACCESS,2008/04/23,09:03:44 -4:00 GMT,Desktop Window Manager was blocked from connecting to the Internet (224.0.0.252).,N/A,N/A
    FWIN,2008/04/23,09:10:42 -4:00 GMT,221.209.110.12:44107,68.205.1.14:1027,UDP
    FWIN,2008/04/23,09:42:06 -4:00 GMT,122.225.1.148:1099,68.205.1.14:1434,UDP
    ACCESS,2008/04/23,09:42:44 -4:00 GMT,Desktop Window Manager was blocked from connecting to the Internet (224.0.0.252).,N/A,N/A
    FWIN,2008/04/23,09:44:42 -4:00 GMT,202.97.238.233:38447,68.205.1.14:1026,UDP
    FWIN,2008/04/23,09:45:46 -4:00 GMT,59.63.157.211:6000,68.205.1.14:8000,TCP (flags:S)
    ACCESS,2008/04/23,09:45:46 -4:00 GMT,System settings protector was temporarily blocked from connecting to the Internet (224.0.0.252).,N/A,N/A
    FWIN,2008/04/23,09:46:42 -4:00 GMT,221.209.110.8:57518,68.205.1.14:1027,UDP
    FWIN,2008/04/23,09:57:16 -4:00 GMT,221.208.208.100:46404,68.205.1.14:1026,UDP
    ACCESS,2008/04/23,09:57:54 -4:00 GMT,Desktop Window Manager was blocked from connecting to the Internet (239.255.255.250).,N/A,N/A
    ACCESS,2008/04/23,09:58:48 -4:00 GMT,Desktop Window Manager was blocked from connecting to the Internet (224.0.0.252).,N/A,N/A
    ACCESS,2008/04/23,11:18:58 -4:00 GMT,Desktop Window Manager was blocked from connecting to the Internet (239.255.255.250).,N/A,N/A
    ACCESS,2008/04/23,11:23:56 -4:00 GMT,Desktop Window Manager was blocked from connecting to the Internet (224.0.0.252).,N/A,N/A
    ACCESS,2008/04/23,12:04:56 -4:00 GMT,Desktop Window Manager was blocked from connecting to the Internet (239.255.255.250).,N/A,N/A
    ACCESS,2008/04/23,13:09:04 -4:00 GMT,Desktop Window Manager was blocked from connecting to the Internet (239.255.255.250).,N/A,N/A
    PE,2008/04/23,13:53:04 -4:00 GMT,Adobe Flash Player Helper 9.0
    r115,C:\Windows\System32\Macromed\Flash\FlashUtil9 e.exe,224.0.0.252:0,N/A
    PE,2008/04/23,13:54:12 -4:00 GMT,Adobe Flash Player Helper 9.0
    r115,C:\Windows\System32\Macromed\Flash\FlashUtil9 e.exe,239.255.255.250:0,N/A
    ACCESS,2008/04/23,14:45:10 -4:00 GMT,Desktop Window Manager was blocked from connecting to the Internet (224.0.0.252).,N/A,N/A
    PE,2008/04/23,15:35:04 -4:00 GMT,Services and Controller app,C:\Windows\System32\services.exe,0.0.0.0:49156 ,N/A
    PE,2008/04/23,15:35:08 -4:00 GMT,Local Security Authority Process,C:\Windows\System32\lsass.exe,0.0.0.0:4915 7,N/A
    PE,2008/04/23,15:35:12 -4:00 GMT,Windows Explorer,C:\Windows\explorer.exe,10.193.96.1:0,N/A
    PE,2008/04/23,15:35:22 -4:00 GMT,Local Security Authority Process,C:\Windows\System32\lsass.exe,0.0.0.0:4915 7,N/A
    PE,2008/04/23,15:35:22 -4:00 GMT,Windows Explorer,C:\Windows\explorer.exe,10.193.96.1:0,N/A
    ACCESS,2008/04/23,15:35:22 -4:00 GMT,Windows Explorer was unable to obtain permission for connecting to the Internet (10.193.96.1); access was denied.,N/A,N/A
    ACCESS,2008/04/23,15:42:16 -4:00 GMT,Ribbons Screen Saver was blocked from connecting to the Internet (239.255.255.250).,N/A,N/A
    PE,2008/04/23,16:49:24 -4:00 GMT,System settings protector,C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe,224.0.0.252:0,N/A
    ACCESS,2008/04/23,17:06:00 -4:00 GMT,System settings protector was temporarily blocked from connecting to the Internet (224.0.0.252).,N/A,N/A
    ACCESS,2008/04/23,17:43:34 -4:00 GMT,Ribbons Screen Saver was blocked from connecting to the Internet (224.0.0.252).,N/A,N/A
    ACCESS,2008/04/23,18:42:42 -4:00 GMT,Ribbons Screen Saver was blocked from connecting to the Internet (239.255.255.250).,N/A,N/A

  8. #18
    Join Date
    Dec 2002
    Location
    Mikado Michigan
    Posts
    2,596

    Default Re: Random programs and services trying to gain 'net access.

    Sorry about taking so long to get back to you. Ongoing medical thing.

    Is this still happening?
    My homes are SpywareHammer.com and DonHoover.net and BleepingComputer.com


    Consumer Security - 2011 & 2012

    Tilting at windmills hurts you more than the windmills.
    -From the Notebooks of Lazarus Long
    Senior of the Howard Families

  9. #19
    voivod Guest

    Default Re: Random programs and services trying to gain 'net access.

    Every day, dozens of times a day. Just about every running program and process has caused ZA to kick off an alert about it/them trying to access the net. All are to the IANA private blocks.
    Hope you're feeling better.

  10. #20
    Join Date
    Dec 2002
    Location
    Mikado Michigan
    Posts
    2,596

    Default Re: Random programs and services trying to gain 'net access.

    Are you using the gadgets on the Vista Desktop?
    My homes are SpywareHammer.com and DonHoover.net and BleepingComputer.com


    Consumer Security - 2011 & 2012

    Tilting at windmills hurts you more than the windmills.
    -From the Notebooks of Lazarus Long
    Senior of the Howard Families

Page 2 of 3 FirstFirst 123 LastLast

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •